GraphWorm is a Windows backdoor associated with the China-aligned Webworm threat group. It uses Microsoft Graph API access authenticated as an OAuth application and Microsoft OneDrive storage as its command-and-control channel. The implant creates a victim-specific cloud workspace, retrieves encrypted tasking, uploads encrypted results and collected files, and maintains beacon and host-fingerprinting data. Supported commands include shell execution, process execution, file upload and download, configurable sleep intervals, and self-termination. GraphWorm derives a victim identifier from hardware and system attributes obtained through WMI and encrypts communications using AES-CBC before base64 encoding. It persists across user logon through Windows Registry Run-key modification. It can accept an upgrade task that replaces its OAuth and OneDrive configuration, enabling operators to rotate command-and-control identities without redeploying the implant. Webworm activity involving GraphWorm has been linked to government and other organizations, particularly in Europe, as well as a university in South Africa.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The sample is GraphWorm, a custom implant tied to the China-nexus APT group Webworm.” GraphWorm authenticates to Microsoft Graph as an OAuth application and uses a OneDrive account as a dead drop for encrypted tasking and results.
According to ESET, the group’s latest campaigns introduced two new backdoors: EchoCreep and GraphWorm. GraphWorm relies on Microsoft Graph API and OneDrive endpoints to retrieve tasks and upload victim information.
According to ESET, the group’s latest campaigns introduced two new backdoors: EchoCreep and GraphWorm. GraphWorm relies on Microsoft Graph API and OneDrive endpoints to retrieve tasks and upload victim information.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
GraphWorm and EchoCreep use encryption and encoding techniques to obfuscate data.
EchoCreep backdoor using Discord for C&C. ... GraphWorm backdoor using the Microsoft Graph API for C&C.
“All of it rides graph.microsoft.com over TLS, from a host that is already talking to Microsoft 365 all day.”
WormFrp, ChainWorm, WormSocket, SmuxProxy, and GraphWorm have the capability to connect to external proxies.
“It authenticates to Microsoft Graph as an OAuth application and uses a OneDrive account as a dead drop. The operator writes an encrypted task file into a job folder. The implant polls that folder, runs the task, then uploads the encrypted result into a result folder.”
“The command set covers shell execution, file upload and download.”
EchoCreep, GraphWorm, and WormSocket make use of base64 encoding.
Confirms the published Microsoft Graph + OneDrive C&C role at the file level.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom backdoor/implant that uses Microsoft Graph and attacker-controlled OneDrive accounts for encrypted command-and-control. It supports shell execution, file upload/download, sleep, termination, and key exchange. Its remote “upgrade” command can replace its embedded OAuth client ID, client secret, tenant ID, refresh token, and related configuration, allowing operators to rotate to a different OneDrive application identity without redeploying the implant.
A backdoor referenced in reporting about Webworm using Discord and Microsoft Graph API for command and control.
A more advanced custom backdoor used by Webworm that leverages Microsoft Graph API for C2, can spawn cmd.exe, execute processes, upload/download files via Microsoft OneDrive, and stop its own execution on operator signal.
A Go-based backdoor that uses Microsoft Graph API and OneDrive as its command-and-control channel, creating victim-specific folders to receive tasks, upload/download files, execute shell commands via cmd.exe, and return command output while blending into legitimate cloud traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.